Debian 11027 Published by

Debian LTS issued advisory DLA-4717-1 to update the Linux 5.10 kernel to version 5.10.262-1, addressing dozens of CVEs that could enable privilege escalation, denial of service, or information leaks on Debian 9, 10, and 11 systems. Advisory DLA-4720-1 brings kernel version 6.1.180-1 to Debian 12, resolving comparable security issues and adding fixes for earlier vulnerabilities like CVE-2024-36013. The p7zip package undergoes a significant replacement with 7-Zip version 26.02 under advisory DLA-4719-1, eliminating CVE-2026-14266 which permits remote code execution via XZ heap buffer overflow and CVE-2026-58052 that risks file content spoofing on RAR5 archives. Direct 7zip packages also advance to version 26.02 for Debian 12, while FreeXian extends these p7zip and kernel fixes to Debian 9 and 10 through ELA-1793-1 and ELA-1794-1 for extended lifecycle support.

[DLA 4717-1] linux security update
ELA-1793-1 linux-5.10 security update (by )
[DLA 4720-1] linux security update
[DLA 4719-1] p7zip security update
[DLA 4718-1] 7zip security update
ELA-1794-1 p7zip security update (by )




[SECURITY] [DLA 4717-1] linux security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4717-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
August 05, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : linux
Version : 5.10.262-1
CVE ID : CVE-2022-49803 CVE-2022-50114 CVE-2023-52494 CVE-2025-23131
CVE-2025-39931 CVE-2026-23204 CVE-2026-31451 CVE-2026-31755
CVE-2026-43216 CVE-2026-43219 CVE-2026-43499 CVE-2026-46116
CVE-2026-46135 CVE-2026-46252 CVE-2026-46331 CVE-2026-52942
CVE-2026-53138 CVE-2026-53157 CVE-2026-53158 CVE-2026-53159
CVE-2026-53167 CVE-2026-53177 CVE-2026-53325 CVE-2026-53329
CVE-2026-53332 CVE-2026-53381 CVE-2026-53382 CVE-2026-53385
CVE-2026-53392 CVE-2026-53393 CVE-2026-53397 CVE-2026-53398
CVE-2026-53399 CVE-2026-53400 CVE-2026-53402 CVE-2026-53403
CVE-2026-63794 CVE-2026-63796 CVE-2026-63798 CVE-2026-63800
CVE-2026-63801 CVE-2026-63803 CVE-2026-63806 CVE-2026-63808
CVE-2026-63809 CVE-2026-63814 CVE-2026-63815 CVE-2026-63818
CVE-2026-63822 CVE-2026-63823 CVE-2026-63824 CVE-2026-63827
CVE-2026-63828 CVE-2026-63829 CVE-2026-63830 CVE-2026-63831
CVE-2026-63834 CVE-2026-63835 CVE-2026-63836 CVE-2026-64188
CVE-2026-64189 CVE-2026-64191 CVE-2026-64206 CVE-2026-64249
CVE-2026-64252 CVE-2026-64266 CVE-2026-64268 CVE-2026-64271
CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276
CVE-2026-64277 CVE-2026-64296 CVE-2026-64298 CVE-2026-64299
CVE-2026-64303 CVE-2026-64304 CVE-2026-64306 CVE-2026-64312
CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317
CVE-2026-64318 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324
CVE-2026-64329 CVE-2026-64330 CVE-2026-64331 CVE-2026-64332
CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64337
CVE-2026-64338 CVE-2026-64340 CVE-2026-64342 CVE-2026-64343
CVE-2026-64344 CVE-2026-64345 CVE-2026-64347 CVE-2026-64348
CVE-2026-64351 CVE-2026-64359 CVE-2026-64360 CVE-2026-64361
CVE-2026-64362 CVE-2026-64363 CVE-2026-64364 CVE-2026-64370
CVE-2026-64371 CVE-2026-64372 CVE-2026-64373 CVE-2026-64374
CVE-2026-64375 CVE-2026-64378 CVE-2026-64379 CVE-2026-64380
CVE-2026-64381 CVE-2026-64403 CVE-2026-64406 CVE-2026-64408
CVE-2026-64411 CVE-2026-64412 CVE-2026-64413 CVE-2026-64420
CVE-2026-64422 CVE-2026-64423 CVE-2026-64425 CVE-2026-64429
CVE-2026-64435 CVE-2026-64436 CVE-2026-64438 CVE-2026-64442
CVE-2026-64445 CVE-2026-64446 CVE-2026-64448 CVE-2026-64450
CVE-2026-64452 CVE-2026-64455 CVE-2026-64456 CVE-2026-64461
CVE-2026-64462 CVE-2026-64465 CVE-2026-64468 CVE-2026-64469
CVE-2026-64470 CVE-2026-64471 CVE-2026-64475 CVE-2026-64478
CVE-2026-64483 CVE-2026-64484 CVE-2026-64487 CVE-2026-64488
CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497
CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505
CVE-2026-64510 CVE-2026-64514 CVE-2026-64529 CVE-2026-64534
CVE-2026-64538 CVE-2026-64540 CVE-2026-64541 CVE-2026-64544
CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549
CVE-2026-64550 CVE-2026-64551 CVE-2026-64553 CVE-2026-64554
CVE-2026-64560

Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.

For Debian 11 bullseye, these problems have been fixed in version
5.10.262-1. This version additionally includes many more bug fixes
from stable updates 5.10.260-5.10.262.

We recommend that you upgrade your linux packages.

For the detailed security status of linux please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/linux

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

ELA-1793-1 linux-5.10 security update (by )


Package : linux-5.10


Version : 5.10.262-1~deb9u1 (stretch), 5.10.262-1~deb10u1 (buster)


Related CVEs :

CVE-2022-49803

CVE-2022-50114

CVE-2023-52494

CVE-2025-23131

CVE-2025-39931

CVE-2026-23204

CVE-2026-31451

CVE-2026-31755

CVE-2026-43216

CVE-2026-43219

CVE-2026-43499

CVE-2026-46116

CVE-2026-46135

CVE-2026-46252

CVE-2026-46331

CVE-2026-52942

CVE-2026-53138

CVE-2026-53157

CVE-2026-53158

CVE-2026-53159

CVE-2026-53167

CVE-2026-53177

CVE-2026-53325

CVE-2026-53329

CVE-2026-53332

CVE-2026-53381

CVE-2026-53382

CVE-2026-53385

CVE-2026-53392

CVE-2026-53393

CVE-2026-53397

CVE-2026-53398

CVE-2026-53399

CVE-2026-53400

CVE-2026-53402

CVE-2026-53403

CVE-2026-63794

CVE-2026-63796

CVE-2026-63798

CVE-2026-63800

CVE-2026-63801

CVE-2026-63803

CVE-2026-63806

CVE-2026-63808

CVE-2026-63809

CVE-2026-63814

CVE-2026-63815

CVE-2026-63818

CVE-2026-63822

CVE-2026-63823

CVE-2026-63824

CVE-2026-63827

CVE-2026-63828

CVE-2026-63829

CVE-2026-63830

CVE-2026-63831

CVE-2026-63834

CVE-2026-63835

CVE-2026-63836

CVE-2026-64188

CVE-2026-64189

CVE-2026-64191

CVE-2026-64206

CVE-2026-64249

CVE-2026-64252

CVE-2026-64266

CVE-2026-64268

CVE-2026-64271

CVE-2026-64273

CVE-2026-64274

CVE-2026-64275

CVE-2026-64276

CVE-2026-64277

CVE-2026-64296

CVE-2026-64298

CVE-2026-64299

CVE-2026-64303

CVE-2026-64304

CVE-2026-64306

CVE-2026-64312

CVE-2026-64313

CVE-2026-64315

CVE-2026-64316

CVE-2026-64317

CVE-2026-64318

CVE-2026-64322

CVE-2026-64323

CVE-2026-64324

CVE-2026-64329

CVE-2026-64330

CVE-2026-64331

CVE-2026-64332

CVE-2026-64333

CVE-2026-64334

CVE-2026-64335

CVE-2026-64337

CVE-2026-64338

CVE-2026-64340

CVE-2026-64342

CVE-2026-64343

CVE-2026-64344

CVE-2026-64345

CVE-2026-64347

CVE-2026-64348

CVE-2026-64351

CVE-2026-64359

CVE-2026-64360

CVE-2026-64361

CVE-2026-64362

CVE-2026-64363

CVE-2026-64364

CVE-2026-64370

CVE-2026-64371

CVE-2026-64372

CVE-2026-64373

CVE-2026-64374

CVE-2026-64375

CVE-2026-64378

CVE-2026-64379

CVE-2026-64380

CVE-2026-64381

CVE-2026-64403

CVE-2026-64406

CVE-2026-64408

CVE-2026-64411

CVE-2026-64412

CVE-2026-64413

CVE-2026-64420

CVE-2026-64422

CVE-2026-64423

CVE-2026-64425

CVE-2026-64429

CVE-2026-64435

CVE-2026-64436

CVE-2026-64438

CVE-2026-64442

CVE-2026-64445

CVE-2026-64446

CVE-2026-64448

CVE-2026-64450

CVE-2026-64452

CVE-2026-64455

CVE-2026-64456

CVE-2026-64461

CVE-2026-64462

CVE-2026-64465

CVE-2026-64468

CVE-2026-64469

CVE-2026-64470

CVE-2026-64471

CVE-2026-64475

CVE-2026-64478

CVE-2026-64483

CVE-2026-64484

CVE-2026-64487

CVE-2026-64488

CVE-2026-64494

CVE-2026-64495

CVE-2026-64496

CVE-2026-64497

CVE-2026-64500

CVE-2026-64503

CVE-2026-64504

CVE-2026-64505

CVE-2026-64510

CVE-2026-64514

CVE-2026-64529

CVE-2026-64534

CVE-2026-64538

CVE-2026-64540

CVE-2026-64541

CVE-2026-64544

CVE-2026-64546

CVE-2026-64547

CVE-2026-64548

CVE-2026-64549

CVE-2026-64550

CVE-2026-64551

CVE-2026-64553

CVE-2026-64554

CVE-2026-64560



Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
This version additionally includes many more bug fixes
from stable updates 5.10.260-5.10.262.


ELA-1793-1 linux-5.10 security update (by )



[SECURITY] [DLA 4720-1] linux security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4720-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Ben Hutchings
August 05, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : linux
Version : 6.1.180-1
CVE ID : CVE-2024-36013 CVE-2025-40196 CVE-2026-31610 CVE-2026-43216
CVE-2026-46135 CVE-2026-53332 CVE-2026-53392 CVE-2026-53393
CVE-2026-53399 CVE-2026-53400 CVE-2026-53402 CVE-2026-63797
CVE-2026-63806 CVE-2026-63810 CVE-2026-63815 CVE-2026-63818
CVE-2026-63829 CVE-2026-64187 CVE-2026-64189 CVE-2026-64206
CVE-2026-64248 CVE-2026-64250 CVE-2026-64266 CVE-2026-64268
CVE-2026-64269 CVE-2026-64271 CVE-2026-64273 CVE-2026-64274
CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64279
CVE-2026-64296 CVE-2026-64297 CVE-2026-64298 CVE-2026-64299
CVE-2026-64301 CVE-2026-64303 CVE-2026-64304 CVE-2026-64306
CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316
CVE-2026-64317 CVE-2026-64318 CVE-2026-64322 CVE-2026-64323
CVE-2026-64324 CVE-2026-64329 CVE-2026-64330 CVE-2026-64331
CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335
CVE-2026-64336 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340
CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64346
CVE-2026-64347 CVE-2026-64350 CVE-2026-64351 CVE-2026-64352
CVE-2026-64355 CVE-2026-64359 CVE-2026-64360 CVE-2026-64361
CVE-2026-64362 CVE-2026-64363 CVE-2026-64364 CVE-2026-64365
CVE-2026-64370 CVE-2026-64371 CVE-2026-64372 CVE-2026-64373
CVE-2026-64374 CVE-2026-64375 CVE-2026-64376 CVE-2026-64378
CVE-2026-64379 CVE-2026-64380 CVE-2026-64381 CVE-2026-64390
CVE-2026-64393 CVE-2026-64394 CVE-2026-64395 CVE-2026-64396
CVE-2026-64397 CVE-2026-64398 CVE-2026-64399 CVE-2026-64401
CVE-2026-64403 CVE-2026-64406 CVE-2026-64408 CVE-2026-64409
CVE-2026-64411 CVE-2026-64412 CVE-2026-64413 CVE-2026-64417
CVE-2026-64419 CVE-2026-64420 CVE-2026-64422 CVE-2026-64423
CVE-2026-64425 CVE-2026-64428 CVE-2026-64429 CVE-2026-64430
CVE-2026-64432 CVE-2026-64435 CVE-2026-64436 CVE-2026-64437
CVE-2026-64438 CVE-2026-64440 CVE-2026-64441 CVE-2026-64442
CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64446
CVE-2026-64448 CVE-2026-64449 CVE-2026-64450 CVE-2026-64452
CVE-2026-64454 CVE-2026-64455 CVE-2026-64456 CVE-2026-64458
CVE-2026-64461 CVE-2026-64462 CVE-2026-64465 CVE-2026-64468
CVE-2026-64469 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472
CVE-2026-64475 CVE-2026-64476 CVE-2026-64478 CVE-2026-64480
CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486
CVE-2026-64487 CVE-2026-64488 CVE-2026-64489 CVE-2026-64494
CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64500
CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64510
CVE-2026-64512 CVE-2026-64514 CVE-2026-64530 CVE-2026-64531
CVE-2026-64532 CVE-2026-64533 CVE-2026-64534 CVE-2026-64535
CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539
CVE-2026-64540 CVE-2026-64541 CVE-2026-64544 CVE-2026-64545
CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549
CVE-2026-64550 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553
CVE-2026-64554 CVE-2026-64557 CVE-2026-64560 CVE-2026-64600

Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.

For Debian 12 bookworm, these problems have been fixed in version
6.1.180-1. This version additionally includes many more bug fixes
from stable update 6.1.178-6.1.180.

We recommend that you upgrade your linux packages.

For the detailed security status of linux please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/linux

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



[SECURITY] [DLA 4719-1] p7zip security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4719-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Sylvain Beucler
August 05, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : p7zip
Version : 16.02+really26.02+dfsg-0+deb11u1
16.02+really26.02+dfsg-0+deb12u1
CVE ID : CVE-2026-14266 CVE-2026-58052
Debian Bug : 1142293

Multiple vulnerabilities were discovered in p7zip, a now unmaintained
fork of 7-Zip, which itself is a file archiver handling multiple
formats.

To address these security vulnerabilities, whose fixes unfortunately
cannot be isolated, this update again replaces p7zip with a recent
7-Zip (now v26.02), slightly modified to make it reasonably compatible
with p7zip.

Among the fixed vulnerabilities, the following were made public:

CVE-2026-14266

XZ decompression heap-based buffer overflow, potentially leading
to remote code execution.

CVE-2026-58052

RAR5 alternate-stream handling issue, when running on an NTFS
filesystem with transparent ADS (Alternate Data Stream) and ADS
canonicalization, letting an attacker defeat Mark-of-the-Web
warnings and spoof file content.

For Debian 11 bullseye, these problems have been fixed in version
16.02+really26.02+dfsg-0+deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
16.02+really26.02+dfsg-0+deb12u1.

We recommend that you upgrade your p7zip packages.

For the detailed security status of p7zip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/p7zip

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DLA 4718-1] 7zip security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4718-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Sylvain Beucler
August 05, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : 7zip
Version : 22.01+really26.02+dfsg-0+deb12u1
CVE ID : CVE-2026-14266 CVE-2026-58052
Debian Bug : 1142293

Multiple vulnerabilities were discovered in 7-Zip, a file archiver
handling multiple formats.

Among the fixed vulnerabilities, the following were made public:

CVE-2026-14266

XZ decompression heap-based buffer overflow, potentially leading
to remote code execution.

CVE-2026-58052

RAR5 alternate-stream handling issue, when running on an NTFS
filesystem with transparent ADS (Alternate Data Stream) and ADS
canonicalization, letting an attacker defeat Mark-of-the-Web
warnings and spoof file content.

For Debian 12 bookworm, these problems have been fixed in version
22.01+really26.02+dfsg-0+deb12u1.

We recommend that you upgrade your 7zip packages.

For the detailed security status of 7zip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/7zip

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

ELA-1794-1 p7zip security update (by )


Package : p7zip


Version : 16.02+really26.02+dfsg-0+deb9u1 (stretch), 16.02+really26.02+dfsg-0+deb10u1 (buster)


Related CVEs :

CVE-2026-14266

CVE-2026-58052



Multiple vulnerabilities were discovered in p7zip, a now unmaintained
fork of 7-Zip, which itself is a file archiver handling multiple
formats.
To address these security vulnerabilities, whose fixes unfortunately
cannot be isolated, this update again replaces p7zip with a recent
7-Zip (now v26.02), slightly modified to make it reasonably compatible
with p7zip.
Among the fixed vulnerabilities, the following were made public:


CVE-2026-14266
XZ decompression heap-based buffer overflow, potentially leading
to remote code execution.


CVE-2026-58052
RAR5 alternate-stream handling issue, when running on an NTFS
filesystem with transparent ADS (Alternate Data Stream) and ADS
canonicalization, letting an attacker defeat Mark-of-the-Web
warnings and spoof file content.


ELA-1794-1 p7zip security update (by )